This page explains how to delete your OxSlate data, what is removed, and what is kept and for
how long. It applies to the supporter — the person who keeps the queue and
sends reminders. The recipient never has an account, so there is nothing on our
servers tied to them to delete; their part is covered under the recipient
below.
You do not need an account to use OxSlate, so you may have no server-side data at all.
An email address is optional and exists only so a supporter can recover their queue on a new
phone. If you never added one, the only data is on your device, and uninstalling removes it.
Delete everything from the app
The most complete deletion, and it needs no request to us:
Open OxSlate and go to Settings.
If you added an email address, choose Sign out. This removes the address
from the device immediately.
Choose Disconnect to end the connection. This deletes the queue from the
recipient's device and stops all delivery.
Uninstall the app. Backups are disabled, so nothing is copied to a cloud account or carried
to a new phone.
Delete your server-side account by request
If you added an email address and want the data held under it erased from our servers —
the hashed address and the list of connections it can recover — email us and we will delete
it. You do not need the app installed to make this request.
Email [email protected]
from the address you signed in with, with the subject Account deletion request.
We confirm the request and delete the associated records within 30 days, usually sooner.
We reply to confirm once it is done.
Sending from the sign-in address is how we confirm the request is yours. If you can no longer
use that address, say so in the message and we will find another way to verify before deleting.
What is deleted
Data
When
The one-way hash of your email address
On request, within 30 days
The list of connections recoverable by that address
On request, within 30 days
The device identifier and access token for this device
On uninstall / sign-out
The queue on the recipient's device
Immediately on disconnect
Reminder content held for delivery
When the connection ends
Sign-in codes
Automatically, 10 minutes after issue or as soon as used
What is kept, and why
A small amount of data may be retained after a deletion request, only where the law requires it
or where it exists for the safety of the other person:
Records of completed purchases are held by Google Play and RevenueCat for
their own tax and accounting obligations. We do not control that retention; see their
policies. We hold only your current subscription status, which is removed with your account.
Reminders already delivered to a recipient stay on the recipient's device
until they act on them or disconnect. This is deliberate: a supporter deleting their own
account does not reach onto another person's phone and remove reminders that person may still
be relying on. Ending the connection stops anything further; it does not confiscate what has
already arrived.
If an email address is never used to sign in again, the hashed address and its recoverable
connections expire automatically after about thirteen months, whether or not you make a request.
If you are the recipient
You have no account and were never asked for an email address, so there is nothing on our
servers under your name to delete. You control your own copy directly, at any time and without
giving a reason:
Pause stops anything from arriving until you turn it back on.
Stop ends a single reminder.
Disconnect ends the connection and deletes the queue from your device.
The supporter cannot undo this; reconnecting requires a fresh invitation you choose to accept.
Uninstalling removes everything the app stored on your device.